MH.

Cybersecurity • SOC • Incident Response

Mosab Hassan

Mosab Hassan portrait

Available for freelance & security projects.

About

SOC-focused Cybersecurity & Incident Response engineer. I build detection-ready labs and practical security automation.

What I do

  • Threat detection & alert triage workflows
  • SIEM pipelines (log onboarding, parsing, correlation)
  • Incident Response playbooks and investigation notes
  • Hands-on security labs (blue + red perspective)

Focus areas

SOC SIEM Wazuh Threat Hunting IDS/IPS Linux Automation Detection Engineering

Skills

Core technical stack and operational skills.

Security Operations

  • Incident Response (triage → containment → recovery)
  • Threat Hunting & log analysis
  • Detection tuning & alert prioritization
  • Reporting & security documentation

Network Security

  • Snort / Suricata concepts
  • Firewall rules & segmentation
  • Traffic analysis (PCAP basics)
  • Hardening & baseline controls

Automation

  • Python scripting for security tasks
  • Bash & Linux administration
  • Parsing / normalization helpers
  • Operational checklists & tooling

Projects

SOC Lab Deployment

Blue Team

Built a SOC environment with log sources, agents, and basic correlation logic for common attack patterns.

WazuhSIEMLinux

AI-based IDS

Detection

Implemented anomaly detection for network behavior and a simple prioritization workflow for triage.

PythonMLSOC

CTF Writeups

Offense → Defense

Documented exploitation paths, persistence checks, and remediation notes in a structured format.

WriteupsIR NotesLabs

FireRobot-SAFE

IoT

ESP32-based project focusing on secure control logic and access protections for IoT security practice.

ESP32SecurityEmbedded